CVE 9.8 CRITICAL

Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()_CVE-2026-28780

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server.
If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy_ajp and cause it to write 4 attacker controlled bytes after the end of a heap based buffer.

This issue affects Apache HTTP Server: through 2.4.66.

Users are recommended to upgrade to version 2.4.67, which fixes the issue.

AI Analysis

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server

Basic Information

ID CVE-2026-28780
Source apache
Published May 5, 2026 at 21:29
Modified May 6, 2026 at 15:50

Affected Product

Vendor Apache Software Foundation
Product Apache HTTP Server
Affected Versions Apache Software Foundation Apache HTTP Server 0

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor Apache Foundation
Product Apache HTTP Server
Version through 2.4.66

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.